Total CVEs

140,410

Critical Severity

3,747

High Severity

13,544

Last 7 Days

1,514
Quick preset (or use dates below)
Clear Filters
Showing 7,781 - 7,800 of 13,935 CVEs
CVE-2026-31804 MEDIUM - 4.0

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.0, the /pms_image_proxy endpoint accepts a user-supplied img parameter and forwards it to Plex Media Server's /photo/:/ transcode transcoder without authentication and without restricting the sc...

Vendor: Tautulli
Product: Tautulli
Published: Mar 30, 2026
Source: NVD
CVE-2026-31799 MEDIUM - 4.9

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. From version 2.14.2 to before version 2.17.0 for parameters "before" and "after" and from version 2.1.0-beta to before version 2.17.0 for parameters "section_id" and "user_id", the ...

Vendor: Tautulli
Product: Tautulli
Published: Mar 30, 2026
Source: NVD
CVE-2026-21717 MEDIUM - 5.9

A flaw in V8's string hashing mechanism causes integer-like strings to be hashed to their numeric value, making hash collisions trivially predictable. By crafting a request that causes many such collisions in V8's internal string table, an attacker can significantly degrade performance of ...

Vendor: nodejs
Product: node
Published: Mar 30, 2026
Source: NVD
CVE-2026-21714 MEDIUM - 5.3

A memory leak occurs in Node.js HTTP/2 servers when a client sends WINDOW_UPDATE frames on stream 0 (connection-level) that cause the flow control window to exceed the maximum value of 2ยณยน-1. The server correctly sends a GOAWAY frame, but the Http2Session object is never cleaned up. This vulnerab...

Vendor: nodejs
Product: node
Published: Mar 30, 2026
Source: NVD
CVE-2026-21713 MEDIUM - 5.9

A flaw in Node.js HMAC verification uses a non-constant-time comparison when validating user-provided signatures, potentially leaking timing information proportional to the number of matching bytes. Under certain threat models where high-resolution timing measurements are possible, this behavior cou...

Vendor: nodejs
Product: node
Published: Mar 30, 2026
Source: NVD
CVE-2026-21711 MEDIUM - 5.3

A flaw in Node.js Permission Model network enforcement leaves Unix Domain Socket (UDS) server operations without the required permission checks, while all comparable network paths correctly enforce them. As a result, code running under `--permission` without `--allow-net` can create and expose lo...

Vendor: nodejs
Product: node
Published: Mar 30, 2026
Source: NVD
CVE-2026-5126 MEDIUM - 6.3

A flaw has been found in SourceCodester RSS Feed Parser 1.0. Affected by this issue is the function file_get_contents. This manipulation causes server-side request forgery. The attack is possible to be carried out remotely. The exploit has been published and may be used.

Published: Mar 30, 2026
Source: NVD
CVE-2026-5125 MEDIUM - 5.3

A vulnerability was detected in raine consult-llm-mcp up to 2.5.3. Affected by this vulnerability is the function child_process.execSync of the file src/server.ts. The manipulation of the argument git_diff.base_ref/git_diff.files results in os command injection. The attack is only possible with loca...

Published: Mar 30, 2026
Source: NVD
CVE-2026-33029 MEDIUM - 6.5

Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, an input validation vulnerability in the logrotate configuration allows an authenticated user to cause a complete Denial of Service (DoS). By submitting a negative integer for the rotation interval, the backend enters...

Vendor: 0xJacky
Product: nginx-ui
Published: Mar 30, 2026
Source: NVD
CVE-2026-33027 MEDIUM - 6.5

Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui configuration improperly handles URL-encoded traversal sequences. When specially crafted paths are supplied, the backend resolves them to the base Nginx configuration directory and executes the operation ...

Vendor: 0xJacky
Product: nginx-ui
Published: Mar 30, 2026
Source: NVD
CVE-2026-34373 MEDIUM - 8.8

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.66 and 9.7.0-alpha.10, the GraphQL API endpoint does not respect the allowOrigin server option and unconditionally allows cross-origin requests from any website. This bypasse...

Vendor: npm
Product: parse-server
Published: Mar 30, 2026
Source: GitHub

Sulu is an open-source PHP content management system based on the Symfony framework. From versions 1.0.0 to before 2.6.22, and 3.0.0 to before 3.0.5, a user which has permission for the Sulu Admin via at least one role could have access to the sub-entities of contacts via the admin API without even ...

Vendor: composer
Product: sulu/sulu
Published: Mar 30, 2026
Source: GitHub
CVE-2026-34237 MEDIUM - 6.1

MCP Java SDK is the official Java SDK for Model Context Protocol servers and clients. Prior to versions 1.0.1 and 1.1.1, there is a hardcoded wildcard CORS vulnerability. This issue has been patched in versions 1.0.1 and 1.1.1.

Vendor: maven
Product: io.modelcontextprotocol.sdk:mcp-core
Published: Mar 30, 2026
Source: GitHub
CVE-2026-34360 MEDIUM - 5.8

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.4, the /loadIG HTTP endpoint in the FHIR Validator HTTP service accepts a user-supplied URL via JSON body and makes server-side HTTP requests to it without any hostname, sche...

Vendor: maven
Product: ca.uhn.hapi.fhir:org.hl7.fhir.core
Published: Mar 30, 2026
Source: GitHub
CVE-2026-34231 MEDIUM - 6.1

Slippers is a UI component framework for Django. Prior to version 0.6.3, a Cross-Site Scripting (XSS) vulnerability exists in the {% attrs %} template tag of the slippers Django package. When a context variable containing untrusted data is passed to {% attrs %}, the value is interpolated into an HTM...

Vendor: pip
Product: slippers
Published: Mar 30, 2026
Source: GitHub
CVE-2026-34165 MEDIUM - 5.0

go-git is an extensible git implementation library written in pure Go. From version 5.0.0 to before version 5.17.1, a vulnerability has been identified in which a maliciously crafted .idx file can cause asymmetric memory consumption, potentially exhausting available memory and resulting in a denial-...

Vendor: go
Product: github.com/go-git/go-git/v5
Published: Mar 30, 2026
Source: GitHub
CVE-2026-29909 MEDIUM - 5.3

MRCMS V3.1.2 contains an unauthenticated directory enumeration vulnerability in the file management module. The /admin/file/list.do endpoint lacks authentication controls and proper input validation, allowing remote attackers to enumerate directory contents on the server without any credentials.

Vendor: mrcms
Product: mrcms
Published: Mar 30, 2026
Source: NVD
CVE-2026-27508 MEDIUM - 5.4

Smoothwall Express versions prior to 3.1 Update 13 contain a reflected cross-site scripting vulnerability in the /redirect.cgi endpoint due to improper sanitation of the url parameter. Attackers can craft malicious URLs with javascript: schemes that execute arbitrary JavaScript in victims' brow...

Vendor: Smoothwall
Product: Express
Published: Mar 30, 2026
Source: NVD
CVE-2026-26352 MEDIUM - 5.4

Smoothwall Express versions prior to 3.1 Update 13 contain a stored cross-site scripting vulnerability in the /cgi-bin/vpnmain.cgi script due to improper sanitation of the VPN_IP parameter. Authenticated attackers can inject arbitrary JavaScript through VPN configuration settings that executes when ...

Vendor: Smoothwall
Product: Express
Published: Mar 30, 2026
Source: NVD
CVE-2026-33990 MEDIUM - 9.1

Docker Model Runner (DMR) is software used to manage, run, and deploy AI models using Docker. Prior to version 1.1.25, Docker Model Runner contains an SSRF vulnerability in its OCI registry token exchange flow. When pulling a model, Model Runner follows the realm URL from the registry's WWW-Aut...

Vendor: go
Product: github.com/docker/model-runner
Published: Mar 30, 2026
Source: GitHub